CVE-2026-105865 | Payload CMS up to 3.89.x/4.0.0-canary.33 File Cleanup unrestricted upload
A vulnerability was found in Payload CMS Payload up to 3.89.x/4.0.0-canary.33. It has been rated as problematic. This vulnerability affects unknown code of the component File Cleanup. Performing a manipulation results in unrestricted upload.
This vulnerability is identified as CVE-2026-105865. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More